Weaknesses of type CWE-121

3,832 results

Estouro de buffer na pilha

Ocorre quando um programa escreve mais dados em um buffer alocado na pilha do que ele pode conter, sobrescrevendo dados adjacentes (variáveis, endereços de retorno, ponteiros). Um atacante pode explorar isso para executar código arbitrário ou causar travamento.

Example

Um programa lê uma string do usuário com gets() ou strcpy() sem validar o tamanho, copiando 500 bytes para um buffer de 64 bytes. O excesso sobrescreve o endereço de retorno da função, permitindo desviar a execução para código malicioso.

How to mitigate

Use funções seguras (strncpy, fgets, snprintf) que aceitam limite de bytes; implemente verificações de limites explícitas no código; ative proteções do compilador/SO (stack canaries, DEP/NX, ASLR); use linguagens com verificação automática de limites ou ferramentas de análise estática.

CVE-2024-30621MEDIUMTenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.EPSS 0.7%CVE-2023-44419HIGHD-Link DIR-X3260 Prog.cgi Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-14992HIGHTenda AC18 HTTP Request GetParentControlInfo strcpy stack-based overflowEPSS 0.7%CVE-2025-14995HIGHTenda FH1201 SetIpBind sprintf stack-based overflowEPSS 0.7%CVE-2024-1941HIGHDelta Electronics CNCSoft-B Stack-based Buffer OverflowEPSS 0.7%CVE-2021-27239HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmwareEPSS 0.7%CVE-2026-3972HIGHTenda W3 HTTP setcfm formSetCfm stack-based overflowEPSS 0.7%CVE-2023-27333MEDIUMTP-Link Archer AX21 tmpServer Command 0x422 Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-39880HIGHStack-based Buffer Overflow in Delta Electronics CNCSoft-G2EPSS 0.7%CVE-2025-69765HIGHTenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption EPSS 0.7%CVE-2024-30166CRITICALIn Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack EPSS 0.7%CVE-2025-15232HIGHTenda M3 setAdPushInfo formSetAdPushInfo stack-based overflowEPSS 0.7%CVE-2025-15253HIGHTenda M3 exeCommand stack-based overflowEPSS 0.7%CVE-2025-15216HIGHTenda AC23 SetIpMacBind fromSetIpMacBind stack-based overflowEPSS 0.7%CVE-2026-44048HIGHStack buffer overflow via UCS-2 type confusion in convert_charset()EPSS 0.7%CVE-2025-15231HIGHTenda M3 setVlanInfo formSetRemoteVlanInfo stack-based overflowEPSS 0.7%CVE-2025-54400HIGHMultiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crEPSS 0.7%CVE-2025-54401HIGHMultiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crEPSS 0.7%CVE-2026-32661CRITICALStack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote EPSS 0.7%CVE-2025-10392CRITICALMercury KM08-708H GiGA WiFi Wave2 HTTP Header stack-based overflowEPSS 0.7%